Skip to content

NightLedger

NightLedger is a Windows backdoor associated with the Iran-linked threat actor Mirage Kitten, also tracked as UNC1549, Smoke Sandstorm, and Nimbus Manticore.

Profile source: Mallory opens in a new tab

NightLedger

Family profile

NightLedger is a Windows backdoor associated with the Iran-linked threat actor Mirage Kitten, also tracked as UNC1549, Smoke Sandstorm, and Nimbus Manticore. It has been used in long-term cyber-espionage operations targeting organizations across the Middle East and Africa, including entities in aerospace, aviation, defense, telecommunications, government, financial services, and small and medium-sized business environments.

NightLedger is designed for covert post-compromise access and operator tasking. It has been observed masquerading as a legitimate DLL and executing through DLL search-order hijacking alongside a trusted Windows binary, indicating deliberate tradecraft for stealth and execution. The malware communicates with command-and-control infrastructure over HTTPS and supports a broad set of remote-access and post-exploitation functions. Documented capabilities include host and user reconnaissance, directory and logical drive enumeration, process listing and management, arbitrary process execution, file upload and download, file copy and deletion, screenshot capture, DLL loading, beacon interval updates, and collection of Windows diagnostic logs including NetSetup.log. Its command parsing and overall design have been noted as similar to the TWOSTROKE backdoor previously linked to the same actor.

NightLedger has been reported as part of a broader Mirage Kitten intrusion set that also includes the BridgeHead and ArcBridge tunneling tools, which are used to relay traffic and maintain covert access through victim environments. In observed operations, the broader campaign relied on highly targeted spearphishing, including recruitment-themed lures and fake videoconferencing pages delivering malicious archives. The malware and surrounding tooling reflect victim-specific tailoring, operational security, and a sustained focus on intelligence collection rather than financially motivated activity.

Capabilities

  • Defense Evasion
  • Dll Sideloading
  • Exfiltration
  • Post Exploitation
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 14, 2026
Last activity
Aug 14, 2026
Feed role
C2
Host form
0 IP / 2 hostnames

Leading locations

  • US1

Leading providers

  • Namecheap, Inc.1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

Reported operators

Threat actors

2 named in public reporting
Mirage Kitten

The centerpiece of the campaign is NightLedger, a newly identified Windows backdoor attributed to Mirage Kitten... Once loaded, NightLedger contacts its C2 infrastructure over HTTPS and supports a broad range of post-compromise activities including system reconnaissance, process execution, directory enumeration, screenshot capture, file upload and download, process management, and collection of Windows diagnostic logs such as NetSetup.log.

Magic Hound

The intrusions involve the use of a previously undocumented Windows backdoor called NightLedger... The toolset includes NightLedger, a new Windows backdoor for reconnaissance, command execution, file operations, process discovery, and screenshot capture.

MITRE ATT&CK

NightLedger in ATT&CK

17 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.